finds.dev← search

// the find

jhaddix/awsScrape

★ 237 · Go · updated Jan 2024

A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.

A single-file Go tool that walks every AWS IP range and grabs the SSL certificate off each host, grepping the CN/O/OU fields for a keyword or wordlist. Built for recon/OSINT work — finding a company's unlisted infrastructure hiding behind an AWS IP by matching on cert metadata rather than DNS. Useful to pentesters and bug bounty hunters doing asset discovery; not something a typical app developer needs.

The technique itself is solid and well-known in the recon community — cert transparency and live TLS handshakes catch infrastructure that DNS enumeration misses entirely. Concurrency is exposed as a simple flag (-threads) so you can tune it to your bandwidth instead of eating a hardcoded default. Wordlist mode means you're not limited to one keyword per run, so you can check a client's various trading names/products in a single pass. The randomize flag is a thoughtful touch — scanning AWS IPs sequentially is a good way to look like a worm to AWS's abuse detection.

It's one unstructured .go file with no package layout, no tests, and no error handling visible from the README — if a connection hangs or a cert parse fails mid-scan, there's no indication of how gracefully that's handled. There's no resume/checkpoint capability, so a scan killed at 90% through all of AWS's ranges (which is a genuinely long run, as the README admits) means starting over. No CI, no releases, no go.mod pinning — you're building from a single file with whatever dependency versions happen to be on your machine at clone time. Hasn't been touched since January 2024, so any AWS IP range changes or Go toolchain drift since then are on you to work around.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →